www.khan.co.kr AI-Driven Hacking Attacks Target South Korea's Financial Sector
Article Content
- •Multiple South Korean banks were hacked using an AI tool released just two months prior.
- •Tens of thousands of personal information items were compromised during the attacks.
- •An emergency meeting was convened by financial authorities to address the widespread hacking.
Between September 27 and 30, 2026, multiple South Korean banks, including Shinhan, KB Kookmin, and Hana Bank, were targeted by AI-driven hacking attacks utilizing a Chinese-language penetration-testing tool released in July. The attacks exploited weak security in internal systems, leading to the exposure of tens of thousands of personal information items. Financial authorities held a meeting on October 4, 2026, to address the situation as the entire financial sector remains on high alert. The attacks are believed to involve IP addresses from eight countries, complicating the identification of the attackers. The financial sector is now facing increased scrutiny and pressure to enhance security measures against such automated threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Hana Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which banks were affected?
How many records were compromised?
What actions are being taken?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…